Lopalopa
109 CVEs tracked since 2024. Since May 2024, none of them reached CISA KEV.
Lopalopa CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-05 | 21 | 0 |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | 38 | 0 |
| 2024-09 | 5 | 0 |
| 2024-10 | null or fewer | |
| 2024-11 | 20 | 0 |
| 2024-12 | 21 | 0 |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | 4 | 0 |
Products
The products that kept showing up in Lopalopa's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Lopalopa.
- CVE-2025-5214Kashipara Responsive Online Learing Platform course_detail_user_new.php sql injection7.3
- CVE-2025-45321kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.8.8
- CVE-2025-45322kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.8.8
- CVE-2025-45320A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.5.3
- CVE-2024-54935A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to exe...5.4
- CVE-2024-54920A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized dat...9.8
- CVE-2024-54930Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.7.2
- CVE-2024-54928kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,7.2
- CVE-2024-54931A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database acc...9.8
- CVE-2024-54933Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.7.2
- CVE-2024-54929KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.7.2
- CVE-2024-54918Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.9.8
- CVE-2024-54922A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access...7.2
- CVE-2024-54924A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database acc...9.8
- CVE-2024-54938A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.7.5
The record
- Peak rank
- #24 in Aug 2024
- Busiest month shown
- Aug 2024, 38 CVEs
- Months with a KEV entry
- 0 since May 2024
- Monthly snapshots
- 6 since 2024